L2TP VPN sort of working but not routing ALL protocols and traffic
All,
I've been fighting with this for a week, hoping someone can help. I am using two ER605s in a remote office / central office confiuration. The bottom line issue is that I can get some traffic (pings/traceroute) to properly traverse the tunnel but web traffic is not going through the same tunnel. Also note that local traffic (servers on both sides of the VPN) work just fine. For example, I can access the home office ER605 without an issue from the client network through the VPN.
for example, if I traceroute to ip dot me, it properly routes through the VPN and out the home site internet gateway. However, if I, at the same time, open a browser to the same site (ip dot me), it shows my local (client site) internet gateway IP address as where I am coming from (same for showmyipaddress dot com)
Goal: I want ALL traffic (including internet traffic) to go out through the VPN and the home office internet connection, so it can all be managed / monitored / filtered.
Setup:
Home Office:
* Public IP address:100.14.120.12)
* WAN IP Address: 192.168.2.1, /24, 192.168.2.1 (this is behind a site firewall)
* L2TP Server:
WAN: WAN
IPSec Encryption: Auto
Pre-Shared Key: (******)
Status: Enable
* Tunnel List
Mode: Server
Local IP: 192.168.1.15
Remote IP: 166.170.32.178
Remote Local IP: 192.168.3.55
* Network --> LAN
IP Address: 192.168.1.1
255.255.255.0
VLAN: 1
IGMP Prosy: Enable
IGMP Version: V2
Client
* Publix IP Address: (again, hiding for obvious reasons): 192.168.1.72, 255.255.255.0, 192.168.1.1
* Transmission --> Load Balancing: Disabled
* Network / LAN
Name: LAN
VLAN: 1
Isolation: Deisolated
IP Address: 192.168.50.1
Subnet: 255.2555.255.0
DHCP Server: Enable
DHCP relay: Disabled
* VPN --> L2TP Client
Tunnel: Home
WAN: WAN1
server ip: (dns name of home office er605)
IPSec: Encrypted
remore subnet: 0.0.0.0/0
Working Mode: NAT
Status: Enable
* VPN / L2TP / Tunnel List:
Mode: Client
Tunnel: Home
Local IP: 192.168.3.55
Remote IP: 100.14.120.12
Remote Local IP: 192.168.1.15
DNS:8.8.8.8
* Transmission / Routing / Policy Routing:
Service Type: ALL
Source: IPGROUP_ANY
WAN: HOME
Effictive Time: Any
Mode: Only (note, I also tried priority, same result)
Some Screen shots:


....the 2.1 and the phlapa both show it is going out through the home office network.
Any ideas? I've even tried static routes forcing specific addresses through (like this site)...always same result.
